Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
Matt Kruse Calendar Script 2.2 - Arbitrary Command Execution
CVE-2000-0432—remotecgi16 may 2000
The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netopia R-series Routers 4.6.2 - Modifying SNMP Tables
CVE-2000-0379—remotehardware16 may 2000
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Computalynx CProxy Server 3.3 SP2 - Buffer Overflow (Denial of Service) (PoC)
CVE-2000-0395—dosmultiple16 may 2000
Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Stake AntiSniff 1.0.1/Researchers 1.0 - DNS Overflow (3)
CVE-2000-0405—remotemultiple16 may 2000
Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response pa
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KDE 1.1/1.1.1/1.2/2.0 kscd - SHELL Environmental Variable
CVE-2000-0393—locallinux16 may 2000
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variabl
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Stake AntiSniff 1.0.1/Researchers 1.0 - DNS Overflow (1)
CVE-2000-0405—remotemultiple16 may 2000
Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response pa
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
George Burgyan CGI Counter 4.0.2/4.0.7 - Input Validation
CVE-2000-0424—remotecgi15 may 2000
The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Seattle Lab Software Emurl 2.0 - Email Account Access
CVE-2000-0397—remotewindows15 may 2000
The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - FTP Denial of Service (MS01-026)
CVE-2001-0336—doswindows14 may 2000
The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of ser
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Active Movie Control 1.0 - Filetype
CVE-2000-0400—remotewindows13 may 2000
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
John Donoghue Knapster 0.9/1.3.8 - File Access
CVE-2000-0412—remoteunix13 may 2000
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Malformed Filename Request
CVE-2000-0457—remotewindows11 may 2000
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large nu
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Bugzilla 2.4/2.6/2.8/2.10 - Arbitrary Command Execution
CVE-2001-0329—remotecgi11 may 2000
Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Malformed File Extension Denial of Service
CVE-2000-0408—doswindows11 may 2000
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a l
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netscape Communicator 4.5/4.51/4.6/4.61/4.7/4.72/4.73 - '/tmp' Symlink
CVE-2000-0409—localmultiple10 may 2000
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite file
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Etype Eserv 2.9.2 - Logging Buffer Overflow
CVE-2000-0523—remotewindows10 may 2000
Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Matt Wright FormMail 1.6/1.7/1.8 - Environmental Variables Disclosure
CVE-2000-0411—remotemultiple10 may 2000
Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Intel Corporation NetStructure 7110 - Undocumented Password
CVE-2000-0384—localunix08 may 2000
NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable f
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FrontPage 2000 / IIS 4.0/5.0 - Server Extensions Full Path Disclosure
CVE-2000-0413—remotewindows06 may 2000
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the ph
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UltraBoard 1.6 - Denial of Service
CVE-2000-0426—doscgi05 may 2000
UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the S
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Gossamer Threads DBMan 2.0.4 - DBMan Information Leakage
CVE-2000-0381—remotemultiple05 may 2000
The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup informati
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aladdin Knowledge Systems eToken 3.3.3 - eToken PIN Extraction
CVE-2000-0427—localwindows04 may 2000
The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive info
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD 3.4/4.0/5.0 / NetBSD 1.4 - Unaligned IP Option Denial of Service
CVE-2000-0440—dosbsd04 may 2000
NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ultrascripts ultraboard 1.6 - Directory Traversal
CVE-2000-0332—remotecgi03 may 2000
UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a path
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedHat Linux 6.0/6.1/6.2 - 'pam_console' Monitor Activity After Logout
CVE-2000-0378—locallinux03 may 2000
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file desc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cart32 3.0 - 'expdate' Administrative Information Disclosure
CVE-2000-0430—remotewindows03 may 2000
Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows 95/98 - NetBIOS NULL Name
CVE-2000-0347—remotewindows02 may 2000
Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Brecht Claerhout Sniffit 0.3.6 HIP/0.3.7 Beta - Mail Logging Buffer Overflow (1)
CVE-2000-0343—remotemultiple02 may 2000
Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Brecht Claerhout Sniffit 0.3.6 HIP/0.3.7 Beta - Mail Logging Buffer Overflow (2)
CVE-2000-0343—remotemultiple02 may 2000
Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
L-Soft Listserv 1.8 - Web Archives Buffer Overflow
CVE-2000-0425—remotewindows01 may 2000
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary comman
23RIESGO
abrir ↗
← anteriorpágina 612 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.